Zero-Cloud Processing Guarantee

Privacy Policy

Effective Date: September 7, 2026 • Last Updated: September 7, 2026

🛡️ Our Absolute Privacy Commitment

At Redact PDF Online (accessible at redactpdfonline.com), your privacy is our core architectural foundation. Unlike conventional document processing websites that force you to transmit files over the internet to remote cloud servers, we process 100% of your PDF files directly inside your browser memory (RAM) using WebAssembly and HTML5 Canvas technology.

Zero bytes of your document text, images, or metadata ever leave your computer or touch our servers.

1. Information We Do NOT Collect (Your Documents)

Because our software operates strictly on the client side, we have zero access to:

  • No File Uploads: Your PDF files are never sent over the internet to any server.
  • No Text Extraction: We never log, view, or store the text contained in your documents.
  • No Sensitive PII Retention: Detected SSNs, IBANs, emails, and phone numbers remain strictly in your device's memory.
  • No Account Information: No registration, passwords, or credit card details are required.

2. How Client-Side Processing Works

When you select a document on our site:

  1. The browser reads the PDF binary data using the standard HTML5 FileReader API directly in local memory.
  2. Our WebAssembly engine parses the page stream and identifies sensitive data locally using mathematical checksums (ISO 7064 MOD 97-10 for IBANs, Luhn algorithm for Credit Cards, and IRS syntax models for SSNs).
  3. Redaction raster burn-in executes via an isolated offscreen canvas buffer in your browser.
  4. The sanitized PDF is compiled into a local Blob and downloaded straight to your hard drive without any server interaction.

3. Analytics & Technical Log Data

To maintain the availability, speed, and reliability of our web infrastructure (hosted via Cloudflare / Cloudflare Pages), standard non-identifying technical metadata may be collected:

  • Browser type, device operating system, and language preference.
  • Referring URLs and timestamps of page visits.
  • Aggregated performance and caching metrics (e.g., page load speeds, Cloudflare edge routing).

We do not deploy invasive third-party cross-site advertising trackers or sell any user information to data brokers.

4. Regulatory Compliance (GDPR, HIPAA & CCPA)

🇪🇺 GDPR Ready

Because personal data is never transmitted to or processed by our servers, you retain full data sovereignty under GDPR Article 4.

🏥 HIPAA Compatible

Covered entities can safely redact Protected Health Information (PHI) without requiring a Business Associate Agreement (BAA).

🇺🇸 CCPA / CPRA

We do not sell or share personal information under California Consumer Privacy Act provisions.

5. External Libraries & CDNs

Our application loads open-source JavaScript rendering libraries (Mozilla pdf.js and pdf-lib) from public content delivery networks (Cloudflare CDNJS). These libraries are executed in your browser sandbox and do not transmit document payloads to external endpoints.

6. Contact Our Privacy Team

If you have questions, feedback, or security inquiries regarding this Privacy Policy, please contact us: